Jump to content

utorrent doesnt work after PC restart


ngEAr

Recommended Posts

OS XP SP3

No router

Firewall ON , exception added

After each PC restart i need to delete all utorrent files ( appl. data and utorrent folder ) , in order to install utorrent again , cause after pc restart im doubleclicking in the icon and it doesnt start.

BTW icon for .torrent isnt the same like for uTorrent icon.

Link to comment
Share on other sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:00:34, on 2009.03.15.

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\IoctlSvc.exe

C:\WINDOWS\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\Fonts\syn00-E0-4D-06-A0-74\system\smss.exe

C:\Program Files\Razer\DeathAdder\razerhid.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe

C:\Program Files\Razer\DeathAdder\razertra.exe

C:\Program Files\Razer\DeathAdder\razerofa.exe

C:\Program Files\Windows Live\Contacts\wlcomm.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\HnH_Script\mirc.exe

D:\uTorrent\uTorrent.exe

C:\Program Files\Ventrilo\Ventrilo.exe

C:\Program Files\Garena\Garena.exe

C:\Program Files\VentriloMIX\Ventrilo 2.3.0.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [TBMonEx] C:\WINDOWS\Fonts\syn00-E0-4D-06-A0-74\system\smss.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')

O4 - Startup: My_AutoWarkey_Script.lnk = C:\Program Files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

--

End of file - 5589 bytes

Process PID CPU Description Company Name

System Idle Process 0 87.50

Interrupts n/a 1.56 Hardware Interrupts

DPCs n/a 9.38 Deferred Procedure Calls

System 4 1.56

smss.exe 568 Windows NT Session Manager Microsoft Corporation

csrss.exe 616 Client Server Runtime Process Microsoft Corporation

winlogon.exe 640 Windows NT Logon Application Microsoft Corporation

services.exe 684 Services and Controller app Microsoft Corporation

svchost.exe 852 Generic Host Process for Win32 Services Microsoft Corporation

wlcomm.exe 388 Windows Live Communications Platform Microsoft Corporation

svchost.exe 912 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1004 Generic Host Process for Win32 Services Microsoft Corporation

wscntfy.exe 1692 Windows Security Center Notification App Microsoft Corporation

svchost.exe 1052 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1128 Generic Host Process for Win32 Services Microsoft Corporation

spoolsv.exe 1376 Spooler SubSystem App Microsoft Corporation

svchost.exe 1488 Generic Host Process for Win32 Services Microsoft Corporation

NBService.exe 1552 Nero BackItUp Nero AG

nvsvc32.exe 1608 NVIDIA Driver Helper Service, Version 182.08 NVIDIA Corporation

IoctlSvc.exe 1628 PLFlash DeviceIoControl Service Prolific Technology Inc.

svchost.exe 1648 Generic Host Process for Win32 Services Microsoft Corporation

alg.exe 1964 Application Layer Gateway Service Microsoft Corporation

lsass.exe 696 LSA Shell (Export Version) Microsoft Corporation

explorer.exe 1416 Windows Explorer Microsoft Corporation

rundll32.exe 1704 Run a DLL as an App Microsoft Corporation

RTHDCPL.exe 1740 Realtek HD Audio Control Panel Realtek Semiconductor Corp.

rundll32.exe 1924 Run a DLL as an App Microsoft Corporation

smss.exe 1828

ctfmon.exe 1944 CTF Loader Microsoft Corporation

Skype.exe 1952 Skype Skype Technologies S.A.

skypePM.exe 2344 Skype Extras Manager Skype Technologies

Garena.exe 2684 Garena Garena Interactive PTE LTD

procexp.exe 504 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

razerhid.exe 1932 razerhid MFC Application

msnmsgr.exe 1360 Windows Live Messenger Microsoft Corporation

AutoHotkey.exe 836 AutoHotkey

razertra.exe 348 razertra MFC Application

razerofa.exe 308 Razer OFA - On-the-Fly Sensitivity Adjustment Razer Inc.

mirc.exe 2712 mIRC mIRC Co. Ltd.

uTorrent.exe 3744 µTorrent BitTorrent, Inc.

Ventrilo.exe 2460 Ventrilo by Flagship Industries, Inc.

Ventrilo 2.3.0.exe 3120 Ventrilo by Flagship Industries, Inc.

war3.exe 3492 Warcraft III Blizzard Entertainment

Link to comment
Share on other sites

rocess PID CPU Description Company Name

System Idle Process 0 89.23

Interrupts n/a Hardware Interrupts

DPCs n/a 7.69 Deferred Procedure Calls

System 4

smss.exe 568 Windows NT Session Manager Microsoft Corporation

csrss.exe 616 Client Server Runtime Process Microsoft Corporation

winlogon.exe 640 Windows NT Logon Application Microsoft Corporation

services.exe 684 Services and Controller app Microsoft Corporation

svchost.exe 852 Generic Host Process for Win32 Services Microsoft Corporation

wlcomm.exe 388 Windows Live Communications Platform Microsoft Corporation

svchost.exe 912 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1004 Generic Host Process for Win32 Services Microsoft Corporation

wscntfy.exe 1692 Windows Security Center Notification App Microsoft Corporation

svchost.exe 1052 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1128 Generic Host Process for Win32 Services Microsoft Corporation

spoolsv.exe 1376 Spooler SubSystem App Microsoft Corporation

svchost.exe 1488 Generic Host Process for Win32 Services Microsoft Corporation

NBService.exe 1552 Nero BackItUp Nero AG

nvsvc32.exe 1608 NVIDIA Driver Helper Service, Version 182.08 NVIDIA Corporation

IoctlSvc.exe 1628 PLFlash DeviceIoControl Service Prolific Technology Inc.

svchost.exe 1648 Generic Host Process for Win32 Services Microsoft Corporation

alg.exe 1964 Application Layer Gateway Service Microsoft Corporation

lsass.exe 696 LSA Shell (Export Version) Microsoft Corporation

explorer.exe 1416 Windows Explorer Microsoft Corporation

rundll32.exe 1704 Run a DLL as an App Microsoft Corporation

RTHDCPL.exe 1740 Realtek HD Audio Control Panel Realtek Semiconductor Corp.

rundll32.exe 1924 Run a DLL as an App Microsoft Corporation

smss.exe 1828

ctfmon.exe 1944 CTF Loader Microsoft Corporation

Skype.exe 1952 Skype Skype Technologies S.A.

skypePM.exe 2344 Skype Extras Manager Skype Technologies

Garena.exe 2684 Garena Garena Interactive PTE LTD

razerhid.exe 1932 razerhid MFC Application

msnmsgr.exe 1360 Windows Live Messenger Microsoft Corporation

AutoHotkey.exe 836 AutoHotkey

razertra.exe 348 razertra MFC Application

razerofa.exe 308 Razer OFA - On-the-Fly Sensitivity Adjustment Razer Inc.

mirc.exe 2712 mIRC mIRC Co. Ltd.

uTorrent.exe 3744 µTorrent BitTorrent, Inc.

Ventrilo.exe 2460 Ventrilo by Flagship Industries, Inc.

Ventrilo 2.3.0.exe 3120 Ventrilo by Flagship Industries, Inc.

WinRAR.exe 3364 WinRAR archiver Alexander Roshal

procexp.exe 3236 3.08 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

Process: uTorrent.exe Pid: 3744

Name Description Company Name Version

ACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.1.2600.5512

adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.1.2600.5512

ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.1.2600.5512

appHelp.dll Application Compatibility Client Library Microsoft Corporation 5.1.2600.5512

ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.5.2284.1

browseui.dll Shell Browser UI Library Microsoft Corporation 6.0.2900.5512

c_1252.nls

c_1257.nls

CLBCATQ.DLL Microsoft Corporation 2001.12.4414.700

COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.0.2900.5512

comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.0.2900.5512

COMRes.dll Microsoft Corporation 2001.12.4414.700

credui.dll Credential Manager User Interface Microsoft Corporation 5.1.2600.5512

CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.5512

CRYPTUI.dll Microsoft Trust UI Provider Microsoft Corporation 5.131.2600.5512

CSCDLL.dll Offline Network Agent Microsoft Corporation 5.1.2600.5512

cscui.dll Client Side Caching UI Microsoft Corporation 5.1.2600.5512

ctype.nls

davclnt.dll Web DAV Client DLL Microsoft Corporation 5.1.2600.5512

DnsApi.dll DNS Client API DLL Microsoft Corporation 5.1.2600.5625

dot3api.dll 802.3 Autoconfiguration API Microsoft Corporation 5.1.2600.5512

dot3dlg.dll 802.3 UI Helper Microsoft Corporation 5.1.2600.5512

drprov.dll Microsoft Terminal Server Network Provider Microsoft Corporation 5.1.2600.5512

eappcfg.dll Eap Peer Config Microsoft Corporation 5.1.2600.5512

eappprxy.dll Microsoft EAPHost Peer Client DLL Microsoft Corporation 5.1.2600.5512

GDI32.dll GDI Client DLL Microsoft Corporation 5.1.2600.5512

gdiplus.dll Microsoft GDI+ Microsoft Corporation 5.1.3102.5512

hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.1.2600.5512

ieframe.dll Internet Explorer Microsoft Corporation 7.0.6000.16674

iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.0.6000.16674

IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 5.1.2600.5512

IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.1.2600.5512

index.dat

index.dat

index.dat

Iphlpapi.dll IP Helper API Microsoft Corporation 5.1.2600.5512

kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.1.2600.5512

LINKINFO.dll Windows Volume Tracking Microsoft Corporation 5.1.2600.5512

locale.nls

MediaLibraryNSE.dll Nero File Dialog Nero AG 3.3.3.0

MFC80ENU.DLL MFC Language Specific Resources Microsoft Corporation 8.0.50727.762

MFC80U.DLL MFCDLL Shared Library - Retail Version Microsoft Corporation 8.0.50727.762

MPR.dll Multiple Provider Router DLL Microsoft Corporation 5.1.2600.5512

MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.1.2600.5512

MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.1.2600.5512

MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.1.2600.5512

msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.1.2600.5512

MSGINA.dll Windows NT Logon GINA DLL Microsoft Corporation 5.1.2600.5512

MSVCP60.dll Microsoft ® C++ Runtime Library Microsoft Corporation 6.2.3104.0

MSVCP80.dll Microsoft® C++ Runtime Library Microsoft Corporation 8.0.50727.762

MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.0.50727.762

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.2600.5512

mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.1.2600.5625

netapi32.dll Net Win32 API DLL Microsoft Corporation 5.1.2600.5512

NETRAP.dll Net Remote Admin Protocol DLL Microsoft Corporation 5.1.2600.5512

NETSHELL.dll Network Connections Shell Microsoft Corporation 5.1.2600.5512

NETUI0.dll NT LM UI Common Code - GUI Classes Microsoft Corporation 5.1.2600.5512

NETUI1.dll NT LM UI Common Code - Networking classes Microsoft Corporation 5.1.2600.5512

Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.0.5441.0

ntdll.dll NT Layer DLL Microsoft Corporation 5.1.2600.5512

ntlanman.dll Microsoft® Lan Manager Microsoft Corporation 5.1.2600.5512

ntshrui.dll Shell extensions for sharing Microsoft Corporation 5.1.2600.5512

ODBC32.dll Microsoft Data Access - ODBC Driver Manager Microsoft Corporation 3.525.1132.0

odbcint.dll Microsoft Data Access - ODBC Resources Microsoft Corporation 3.525.1132.0

ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.1.2600.5512

oleaut32.dll Microsoft Corporation 5.1.2600.5512

OneX.DLL IEEE 802.1X supplicant library Microsoft Corporation 5.1.2600.5512

portabledeviceapi.dll Windows Portable Device API Components Microsoft Corporation 5.2.5721.5145

psapi.dll Process Status Helper Microsoft Corporation 5.1.2600.5512

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.1.2600.5512

RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.1.2600.5512

rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 5.1.2600.5507

rtutils.dll Routing Utilities Microsoft Corporation 5.1.2600.5512

SAMLIB.dll SAM Library DLL Microsoft Corporation 5.1.2600.5512

Secur32.dll Security Support Provider Interface Microsoft Corporation 5.1.2600.5512

SETUPAPI.dll Windows Setup API Microsoft Corporation 5.1.2600.5512

shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation 6.0.2900.5512

SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.0.2900.5512

shfolder.dll Shell Folder Service Microsoft Corporation 6.0.2900.5512

SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.0.2900.5512

sortkey.nls

sorttbls.nls

unicode.nls

urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.0.6000.16674

USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.1.2600.5512

USERENV.dll Userenv Microsoft Corporation 5.1.2600.5512

uTorrent.exe µTorrent BitTorrent, Inc. 1.8.2.14458

UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.0.2900.5512

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.1.2600.5512

WININET.dll Internet Extensions for Win32 Microsoft Corporation 7.0.6000.16674

WINSTA.dll Winstation Library Microsoft Corporation 5.1.2600.5512

WINTRUST.dll Microsoft Trust Verification APIs Microsoft Corporation 5.131.2600.5512

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.1.2600.5512

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.1.2600.5512

WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.1.2600.5512

wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.1.2600.5512

WTSAPI32.dll Windows Terminal Server SDK APIs Microsoft Corporation 5.1.2600.5512

xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.1.2600.5512

Link to comment
Share on other sites

MediaLibraryNSE.dll Nero File Dialog Nero AG 3.3.3.0

I think it's relative to this exe:

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

Uninstall it and check if the pbm is still here. Anyway this process is known to be the the source of another issue not this one.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...